Cisco yesterday released security patches for two high-severity vulnerabilities affecting its IOS XR software that were found exploited in the wild a month ago. Details for both zero-day unauthenticated DoS vulnerabilities were made public by Cisco late last month. Both vulnerabilities existed due to incorrect implementation of queue management for Internet Group Management Protocol (IGMP) packets on affected devices. The vulnerabilities affect all Cisco devices running any release of Cisco’s software if an active interface is configured under multicast routing, and it is receiving DVMRP traffic.”]

